
Last updated: July 2026
Mylog.watch is a service operated by RVJ WEB. For any question regarding your personal data, you can contact us at contact@rvj-web.com.
When you connect your Google account, we collect and store the following data: • Your Google account information: name, email address, and profile picture. • Your YouTube subscription list: channel names, IDs, and thumbnails. • Video metadata from your subscribed channels: titles, durations, publication dates, and thumbnails. This data is fetched via the YouTube Data API and is not shared with third parties. • Your watch states: for each video, whether you have marked it as seen, skipped, or left it unseen. • Aggregated statistics: daily watch time, finish rates, and backlog size — computed from your watch states. • A server-side session cookie used to keep you logged in.
Your data is used exclusively to provide the Mylog.watch service: • Displaying your subscription feed and video backlog. • Computing watch statistics and insights. • Building smart playlists tailored to your viewing habits. We do not sell, rent, or share your personal data with any third party. We do not post anything to YouTube on your behalf. The YouTube API access is strictly read-only.
The processing of your personal data is based on your consent, given when you authorize Mylog.watch to access your Google account via the OAuth 2.0 flow. You may withdraw this consent at any time by disconnecting your account from the Settings page.
Your data is retained for as long as your account exists. You can permanently delete your account and all associated data from the Settings page (Danger zone → Delete account). Upon deletion, all personal data, watch states, and statistics are immediately and irreversibly erased from our servers. The session cookie expires 30 days after your last sign-in, or immediately when you log out.
We treat your Google OAuth tokens and YouTube data as sensitive data and protect them with the following measures: • Encryption in transit: all traffic between your browser, our servers, and the Google APIs uses HTTPS with TLS 1.2 or higher. • Encryption at rest: your Google OAuth tokens are encrypted with AES-256-GCM at the application layer before being written to the database, so they cannot be read from a database dump or backup. The encryption key is stored in a dedicated secrets manager, never in our database or source code. The underlying database storage is additionally encrypted at rest with AES-256 by our hosting provider. • Session cookies are signed and encrypted, and set with the HttpOnly, Secure, and SameSite=Lax flags to mitigate theft and cross-site request forgery. Administrative access to the production database is restricted to the service operator, protected by multi-factor authentication, and used only for maintenance. • Least privilege: we request the narrowest Google scope that makes the product work (youtube.readonly). This access is read-only — we cannot and do not post, modify, or delete anything on your YouTube account. • Deletion and revocation: deleting your account immediately removes your tokens and personal data from our database and revokes our access token with Google. You may also revoke access at any time from your Google Account permissions page. • Incident response: if a breach affecting your personal data occurs, we will notify the CNIL within 72 hours and inform affected users without undue delay, as required by the GDPR. No system can be guaranteed perfectly secure, but we review these measures regularly and apply security updates to our dependencies.
Under the GDPR, you have the following rights regarding your personal data: • Right of access: you can request a copy of your data via Settings → Export my data. • Right to rectification: contact us at contact@rvj-web.com. • Right to erasure: delete your account from Settings → Danger zone. • Right to data portability: use the JSON export in Settings. • Right to lodge a complaint: you may file a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés) at www.cnil.fr. For any request, contact: contact@rvj-web.com.
Mylog.watch uses YouTube API Services to read your subscriptions and the videos your channels publish. By using Mylog.watch you also agree to the YouTube Terms of Service, and your use of data is subject to the Google Privacy Policy:
You can review or revoke Mylog.watch's access to your Google account at any time from the Google security settings: Google account permissions.